Bug #67639 [Opn->Nab]: cURL returns HTTP 400 error when doing two back-to-back queries
| From: | mike@php.net | Date: | Tue, 26 Mar 2019 17:36:03 +0000 |
| Subject: | Bug #67639 [Opn->Nab]: cURL returns HTTP 400 error when doing two back-to-back queries | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220206@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67639&edit=1
ID: 67639
Updated by: mike@php.net
Reported by: jarkkohyvarinen at hotmail dot com
Summary: cURL returns HTTP 400 error when doing two
back-to-back queries
-Status: Open
+Status: Not a bug
Type: Bug
Package: cURL related
Operating System: CentOS 6.5
PHP Version: 5.5.14
Block user comment: N
Private report: N
New Comment:
.
Previous Comments:
------------------------------------------------------------------------
[2015-07-27 12:46:37] lukas at owncloud dot com
This is caused by an upstream NSS bug: https://bugzilla.redhat.com/show_bug.cgi?id=1241172
------------------------------------------------------------------------
[2014-07-17 10:56:58] jarkkohyvarinen at hotmail dot com
I noticed that if CURLOPT_SSL_VERIFYPEER is set to FALSE then both queries executes successfully.
------------------------------------------------------------------------
[2014-07-17 09:46:46] jarkkohyvarinen at hotmail dot com
Description:
------------
If I do two back-to-back queries to our server using two different server aliases (pointing to same
server) first query executes successfully but second query always causes HTTP error 400.
Apache ssl_error_log has an "Hostname www.server.com provided via SNI and hostname
alias.server.com provided via HTTP are different" describing the 400 error.
Our server has Apache 2.2.15, OpenSSL 1.0.1e and cURL 7.19.7.
---
Workaround is to use stream_context_create with SNI_enabled and SNI_server_name options.
Test script:
---------------
function doCurl($url) {
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$result = curl_exec($ch);
$code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
return $code;
}
echo "HTTP Status: ".doCurl("https://www.server.com")."\n";
echo "HTTP Status: ".doCurl("https://alias.server.com")."\n";
Expected result:
----------------
HTTP Status: 200
HTTP Status: 200
Actual result:
--------------
HTTP Status: 200
HTTP Status: 400
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67639&edit=1